CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Nokia And IPSO
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-29
eyunghans eyunghans is offline
Junior Member
 
Join Date: 2006-03-28
Location: Oakland, CA
Posts: 14
Rep Power: 0
eyunghans has an average reputation (10+)
Default Options for network monitoring/trending a Nokia appliance?

All-

First, let me begin by saying this site has been a fantastic resource... There is a wealth of info available here! This is my first post so please bare with me if this has been answered before... I was unable to find any info in my searches.

For some background I am just starting to take over most firewall duties for our company. We currently have about 35 distributed sites in total using Traditional mode VPN configuration. Some sites are utilizing Windows-based Checkpoint boxes and some are using Nokia-based appliances.

We are trying to figure out what are options are for performing network monitoring on our Nokia-based platforms, preferably using opensource applications. We are currently using ntop on our Windows machines which is exactly what we need. Is there anything comparable for the Nokia-based devices? Do they support sFlow/netflow so I could pass the data to another ntop server?

Thanks again,
eyunghans

Last edited by eyunghans; 2006-03-29 at 15:03.
Reply With Quote
  #2 (permalink)  
Old 2006-03-29
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: Options for network monitoring/trending a Nokia appliance?

What version are you running? You can try this almost free product:
FW Logging

By the way, what is wrong with Eventia Reporter and SmartView Monitor?
Reply With Quote
  #3 (permalink)  
Old 2006-03-29
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Options for network monitoring/trending a Nokia appliance?

You can use MRTG (it will monitor SNMP network devices) for monitoring.
Reply With Quote
  #4 (permalink)  
Old 2006-04-03
eyunghans eyunghans is offline
Junior Member
 
Join Date: 2006-03-28
Location: Oakland, CA
Posts: 14
Rep Power: 0
eyunghans has an average reputation (10+)
Default Re: Options for network monitoring/trending a Nokia appliance?

Thanks for the quick replies sergev and kva.kva... I'm the slow one to reply to this! :)

sergev-
It looks like both Advent's Firewall Analyzer as well Eventia Reporter require a connection directly to the management station... while that isn't an issue the flood of traffic coming into management station is. If we have 40 firewalls externally deployed (they link our offices around the world), about 1600 total users (with alot more actual computers), and all of them are sending usage data/stats back to our main management station, I could only imagine the traffic generated just by the firewalls could be excessive. To boot our management station is sitting in our home office, which has the most network usage statistically speaking. Is there a way to have a localized station somewhere behind each firewall to collect all of the logs instead of having it go all the way back to our main management station thus plugging up the pipe? It seems like both of these products are exactly what we need, we are just really concerned about the amount of bandwidth these transfer logs are going to generate on a daily basis incoming to that management station...

kva.kva,
We are currently using mrtg to graph our bandwidth, but sadly it won't tell us which user is using a BitTorrent client to download the latest Linux iso and sucking up a full T1... :)

Thanks again,
eyunghans

Last edited by eyunghans; 2006-04-03 at 17:22.
Reply With Quote
  #5 (permalink)  
Old 2006-04-03
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: Options for network monitoring/trending a Nokia appliance?

If I'm not wrong it is possible to set Log Servers on each remote firewall. All the logging will be done locally. During off peak hours the logs will be transferred to the Reporting station (in the center location).

SmartView Monitor do not require big pipe (AFAIK) for real time monitoring.
Eventia Reporter Express reports do not require any raw log transfers also. All the statistics are collected and analyzed on the enforcement point. You only need to tune "SmartView Monitor" settings under remote firewall global properties (and have appropriate license).
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 00:23.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0